Privacy Policy
Last updated: 13/02/2026
Hibiscus Therapy (“we”, “us”, “our”) is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store and protect your personal data when you:
- Visit www.hibiscustherapy.com
- Submit a contact form
- Book or attend hypnotherapy or hypnobirthing services
- Communicate with us by email or telephone
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
-
Who We Are
Hibiscus Therapy provides clinical hypnotherapy and hypnobirthing services in the United Kingdom.
For data protection purposes, Hibiscus Therapy is the Data Controller of your personal data.
Contact:
Email: hello@hibiscustherapy.com
Website: www.hibiscustherapy.com
-
The Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
2.1 Contact & Identity Data
- Full name
- Email address
- Telephone number
- Postal address
- Emergency contact details
- Occupation
2.2 Health & Sensitive Data (Special Category Data)
In order to provide hypnotherapy or hypnobirthing services safely and appropriately, we may collect:
- Medical history
- Mental health history
- Current medical conditions
- Medication information
- Pregnancy and obstetric history
- GP details
- Session notes
- Information relating to emotional wellbeing
This information is collected via client intake forms Hibiscus Therapy – Hypnotherapy…
and course documentation Hibiscus Hypnobirthing Terms & Conditions.
Health information is treated as special category data under UK GDPR and is handled with enhanced confidentiality.
2.3 Website & Technical Data
When you visit our website (hosted on WordPress), certain technical data may automatically be collected, including:
- IP address
- Browser type
- Device information
- Server log information
- Date and time of access
This is collected by our website hosting provider and is used for security and website functionality purposes.
We do not currently run additional analytics tools.
2.4 Payment Data
Hibiscus Therapy does not store or process card payment details.
Payments are processed securely via Square, Inc. (Squareup.com). We do not have access to your full card details.
-
How We Collect Your Data
We collect personal data when you:
- Submit a website contact form
- Complete a hypnotherapy case history form
Hibiscus Therapy – Hypnotherapy…
- Complete hypnobirthing booking documentation
Hibiscus Hypnobirthing Terms & …
- Book sessions
- Communicate via email or phone
- Make a payment via Square
Contact form submissions (name, email and message) are stored securely for a reasonable period to allow communication regarding services.
-
How We Use Your Data
We use your personal data to:
- Respond to enquiries
- Provide hypnotherapy and hypnobirthing services
- Maintain clinical records
- Ensure client safety
- Communicate about appointments
- Send relevant information about services
- Comply with legal or safeguarding obligations
Where we send newsletters or updates, you may unsubscribe at any time by emailing:
“Unsubscribe”
from your registered email address, including your full name, to:
hello@hibiscustherapy.com
-
Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases:
- Consent – for marketing communications
- Contract – to provide booked services
- Legal obligation – where safeguarding or legal duties apply
- Legitimate interests – for responding to enquiries and operating the website
- Explicit consent – for processing special category health data
-
Data Storage & Security
We take appropriate technical and organisational measures to protect your data.
- Paper forms are scanned and stored securely in Microsoft OneDrive
- Hard copies are securely shredded and destroyed
- Digital records are password-protected
- Access is restricted to the therapist only
- Payment processing is handled externally via Square
We retain client records only for as long as necessary to comply with legal, insurance, and professional obligations.
-
Data Sharing
We do not sell, rent or share your personal data with third parties for marketing purposes.
We may share data only:
- Where legally required
- Where there is a safeguarding concern
- With payment processor Square, Inc.
- With IT or hosting providers where necessary for service delivery
If email marketing platforms are used in future, your data may be uploaded solely for communication purposes and will not be sold or shared further.
-
International Transfers
Some third-party providers (such as Square or Microsoft OneDrive) may process data outside the UK.
Where this occurs, appropriate safeguards (such as standard contractual clauses) are in place to ensure data protection compliance.
-
Data Retention
Client records relating to hypnotherapy and hypnobirthing services are retained for 7 years after the date of the final session, in line with professional insurance and legal requirements.
After this period, records are securely deleted or permanently destroyed.
Contact form enquiries are retained for a reasonable period for communication purposes unless you request deletion.
You may request deletion of your personal data at any time, subject to legal, safeguarding, or insurance retention obligations.
-
Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Request correction
- Request deletion
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time
To exercise any of these rights, email: hello@hibiscustherapy.com
-
Complaints
If you are unhappy with how your data has been handled, you may contact us directly.
You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner’s Office
www.ico.org.uk
-
Changes to This Policy
We reserve the right to update this Privacy Policy at any time. The latest version will always be available on our website.
Contact form enquiries are retained for a reasonable period for communication purposes unless you request deletion.
You may request deletion of your personal data at any time, subject to legal, safeguarding, or insurance retention obligations.
